紫色伴侣 - 2006-8-26 12:39:00
这个是日志
Logfile of HijackThis v1.99.1
Scan saved at 12:17:41, on 2006-8-26
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
D:\WINNT\System32\smss.exe
D:\WINNT\system32\winlogon.exe
D:\WINNT\system32\services.exe
D:\WINNT\system32\lsass.exe
D:\WINNT\system32\nvsvc32.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\system32\stisvc.exe
D:\Program Files\WinPoET\WrOS.EXE
D:\WINNT\System32\svchost.exe
D:\WINNT\system32\MSTask.exe
D:\WINNT\System32\WBEM\WinMgmt.exe
D:\WINNT\Explorer.EXE
E:\Program Files\Tencent\qq\QQ.exe
D:\Documents and Settings\sds\My Documents\hijackthis\HijackThis.exe
R3 - Default URLSearchHook is missing
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - e:\Program Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar2.dll
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - D:\WINNT\system32\KakaTool.dll
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [迅雷4] D:\Program Files\Sandai Technologies Inc\Thunder\TDUpdate.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: 上传到QQ网络硬盘 - E:\Program Files\Tencent\qq\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - E:\Program Files\Tencent\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - E:\Program Files\Tencent\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - E:\Program Files\Tencent\qq\SendMMS.htm
O9 - Extra button: 免费精彩视频超流畅在线观看 - {022C4009-5283-4365-97BF-144054B40E2E} - http://itv.mop.com (file missing)
O9 - Extra 'Tools' menuitem: 播霸电视 - {022C4009-5283-4365-97BF-144054B40E2E} - http://itv.mop.com (file missing)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\WINNT\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java 控制台 - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\WINNT\system32\msjava.dll
O9 - Extra button: 浩方对战平台 - {0A155D3C-68E2-4215-A47A-E800A446447A} - E:\Program Files\浩方对战平台\GameClient.exe
O9 - Extra button: Web反病毒保护 - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - E:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINNT\web\related.htm
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - e:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - e:\Program Files\Tencent\QQ\QQIEHelper.dll
O10 - Unknown file in Winsock LSP: d:\winnt\system32\quartz32.dll
O10 - Unknown file in Winsock LSP: d:\winnt\system32\quartz32.dll
O14 - IERESET.INF: SEARCH_PAGE_URL=
O14 - IERESET.INF: START_PAGE_URL=
O16 - DPF: {05C1004E-2596-48E5-8E26-39362985EEB9} (MMCPlayer Class) - http://p3p.sogou.com/MMCShell.cab
O16 - DPF: {098A3F72-3110-4004-B954-2F9DC44934B4} (AddSHCARoot Control) - https://billing.iyoyo.com.cn/Account/AddSHCARootCert.cab
O16 - DPF: {18F57D30-EF36-4C0E-9343-7BFA6DF79B4A} (XLink Class) - http://www.ycdy.com/PSWEdit.CAB
O16 - DPF: {2EA6D939-4445-43F1-A12B-8CB3DDA8B855} (BlueskyVideo Control) - http://www.bluesky.cn/download/v2_60.cab
O16 - DPF: {6D53ADB7-6AD5-4A59-BFE4-7B57D2F4AA89} - http://bar.29183.com/9598.cab
O16 - DPF: {A8C3B40D-5384-44AD-ACC4-504B4D8A85F5} (BoBo_V2 Control) - http://www.vod588.com/BoBo_ActiveX_V2.ocx
O16 - DPF: {A984ED9F-E8DA-44E5-BC18-C14B9ABEF79D} (photo_uploader Control) - http://upload.photo.163.com/photoup.cab
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/pcver2006new/OL2006.cab
O16 - DPF: {FEE1002D-90A5-4A5D-AABE-01803FFBCF7A} (pCastPanel Class) - http://ps.itv.mop.com/dn/files/pCastCtl-1.0.0.90-signed.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E732F341-9519-4A62-A163-441B254B6275}: NameServer = 202.96.209.134 202.96.209.6
O20 - Winlogon Notify: klogon - D:\WINNT\system32\klogon.dll
O20 - Winlogon Notify: System Safety Monitor - D:\WINNT\SYSTEM32\SSMWinlogonEx.dll
O23 - Service: 卡巴斯基反病毒软件6.0 (AVP) - Unknown owner - E:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - D:\WINNT\System32\dmadmin.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - D:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINNT\system32\nvsvc32.exe
O23 - Service: MSIServers (Windows Instaler) - Sygate Technologies, Inc. - (no file)
O23 - Service: WinPPPoverEthernet - iVasion, a Routerware Company - D:\Program Files\WinPoET\WrOS.EXE
我知道010和017肯定是有问题,可是017修复过一会又有了,010用lspfix都清除不掉,各位大哥帮忙想想办法
紫色伴侣 - 2006-8-26 23:48:00
2006-08-26,23:45:10
System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)
Windows 2000 Professional Service Pack 4 (Build 2195)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<NvCplDaemon><RUNDLL32.EXE D:\WINNT\system32\NvCpl.dll,NvStartup> [NVIDIA Corporation]
<Synchronization Manager><mobsync.exe /logon> [Microsoft Corporation]
<迅雷4><D:\Program Files\Sandai Technologies Inc\Thunder\TDUpdate.exe> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [Microsoft Corporation]
<Userinit><D:\WINNT\system32\userinit.exe,> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
<WinlogonNotify: klogon><D:\WINNT\system32\klogon.dll> [Kaspersky Lab]
==================================
启动文件夹
服务
[卡巴斯基反病毒软件6.0 / AVP]
<"E:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r><Kaspersky Lab>
[DuDu Accelerator o / DDDProxy]
<><N/A>
[Logical Disk Manager Administrative Service / dmadmin]
<D:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[Macromedia Licensing Service / Macromedia Licensing Service]
<"D:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe"><N/A>
[mudtx_mudtx_2003_7_24_mud_MUDOS_EXE / mudtx_mudtx_2003_7_24_mud_MUDOS_EXE]
<><N/A>
[NVIDIA Display Driver Service / NVSvc]
<D:\WINNT\system32\nvsvc32.exe><NVIDIA Corporation>
[WINS Client / RpcPatch]
<><N/A>
[MSIServers / Windows Instaler]
<><N/A>
[WinPPPoverEthernet / WinPPPoverEthernet]
<D:\Program Files\WinPoET\WrOS.EXE><iVasion, a Routerware Company>
紫色伴侣 - 2006-8-26 23:48:00
浏览器加载项
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} <e:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[Google Toolbar Helper]
{AA58ED58-01DD-4d91-8333-CF10577473F7} <d:\program files\google\googletoolbar2.dll, Google Inc.>
[Web Browser Applet Control]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} <D:\WINNT\system32\msjava.dll, Microsoft Corporation>
[浩方对战平台]
{0A155D3C-68E2-4215-A47A-E800A446447A} <E:\Program Files\浩方对战平台\GameClient.exe, 上海浩方在线信息技术有限公司>
[Web反病毒保护]
{1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <E:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll, Kaspersky Lab>
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[QQIEFloatBarCfgCmd Class]
{DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <e:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[&Google]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} <d:\program files\google\googletoolbar2.dll, Google Inc.>
[卡卡上网安全助手]
{DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <D:\WINNT\system32\KakaTool.dll, Beijing Rising Technology Co., Ltd.>
[电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <D:\WINNT\system32\msdxm.ocx, Microsoft Corporation>
[Java Plug-in 1.4.2_02]
{8AD9C840-044E-11D1-B3E9-00805F499D93} <D:\Program Files\Java\j2re1.4.2_02\bin\npjpi142_02.dll, JavaSoft / Sun Microsystems, Inc.>
[Java Plug-in 1.4.2_02]
{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBA} <D:\Program Files\Java\j2re1.4.2_02\bin\npjpi142_02.dll, JavaSoft / Sun Microsystems, Inc.>
[上传到QQ网络硬盘]
<E:\Program Files\Tencent\qq\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
<E:\Program Files\Tencent\qq\AddPanel.htm, N/A>
[添加到QQ表情]
<E:\Program Files\Tencent\qq\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<E:\Program Files\Tencent\qq\SendMMS.htm, N/A>
==================================
正在运行的进程
[PID: 180][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.00.2195.6601>
[PID: 132][\??\D:\WINNT\system32\csrss.exe] <Microsoft Corporation><5.00.2195.6601>
[PID: 140][\??\D:\WINNT\system32\winlogon.exe] <Microsoft Corporation><5.00.2195.6997>
[D:\WINNT\system32\klogon.dll] <Kaspersky Lab><6.0.0.299>
[PID: 276][D:\WINNT\system32\services.exe] <Microsoft Corporation><5.00.2195.7035>
[D:\WINNT\system32\quartz32.dll] <><4, 1, 0, 0>
[D:\WINNT\system32\dmserver.dll] <VERITAS Software Corp.><2195.6605.297.3>
[PID: 288][D:\WINNT\system32\lsass.exe] <Microsoft Corporation><5.00.2195.7011>
[PID: 492][D:\WINNT\system32\nvsvc32.exe] <NVIDIA Corporation><6.14.10.7756>
[PID: 524][D:\WINNT\system32\svchost.exe] <Microsoft Corporation><5.00.2134.1>
[D:\WINNT\system32\quartz32.dll] <><4, 1, 0, 0>
[PID: 600][D:\WINNT\system32\stisvc.exe] <Microsoft Corporation><5.00.2195.6656>
[PID: 620][D:\Program Files\WinPoET\WrOS.EXE] <iVasion, a Routerware Company><1, 1, 2, 0>
[D:\Program Files\WinPoET\WrOSControl.dll] <N/A><N/A>
[D:\Program Files\WinPoET\WrFCUtil.dll] <N/A><N/A>
[D:\Program Files\WinPoET\WrEventLog.dll] <N/A><N/A>
[D:\Program Files\WinPoET\WrRTUtil.dll] <N/A><N/A>
[D:\Program Files\WinPoET\WrInterfaceManager.dll] <N/A><N/A>
[D:\Program Files\WinPoET\WrConfig.dll] <N/A><N/A>
[D:\Program Files\WinPoET\WrNetworkDriver.dll] <N/A><N/A>
[D:\Program Files\WinPoET\Wr_Mac_Frames.DLL] <N/A><N/A>
[D:\Program Files\WinPoET\WrPoetDriver.DLL] <N/A><N/A>
[D:\Program Files\WinPoET\WrPacketSock.dll] <N/A><N/A>
[PID: 684][D:\WINNT\System32\svchost.exe] <Microsoft Corporation><5.00.2134.1>
[D:\WINNT\system32\quartz32.dll] <><4, 1, 0, 0>
[PID: 708][D:\WINNT\system32\MSTask.exe] <Microsoft Corporation><4.71.2195.6972>
[D:\WINNT\system32\quartz32.dll] <><4, 1, 0, 0>
[PID: 764][D:\WINNT\System32\WBEM\WinMgmt.exe] <Microsoft Corporation><1.50.1085.0100>
[PID: 916][D:\WINNT\Explorer.EXE] <Microsoft Corporation><5.00.3700.6690>
[E:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\shellex.dll] <Kaspersky Lab><6.0.0.299>
[D:\Program Files\WinRAR\rarext.dll] <N/A><N/A>
[PID: 1128][E:\Program Files\Tencent\qq\QQ.exe] <TENCENT><0, 0, 0, 0>
[E:\Program Files\Tencent\qq\CoralAssist.DLL] <Coral Team><4.5.0 build 20060515>
[E:\Program Files\Tencent\qq\CoralQQ.DLL] <Coral Team><4.5.1 Build 20060620>
[E:\Program Files\Tencent\qq\ipsearcher.dll] <N/A><1.0.0.4>
[E:\Program Files\Tencent\qq\QQBaseClassInDll.dll] <><1, 0, 0, 1>
[E:\Program Files\Tencent\qq\QQHelperDll.dll] <><1, 0, 0, 1>
[E:\Program Files\Tencent\qq\BasicCtrlDll.dll] <Tencent><5, 0, 200, 160>
[E:\Program Files\Tencent\qq\QQAPI.dll] <><1, 0, 0, 1>
[E:\Program Files\Tencent\qq\TIMProxy.dll] <tencent><0, 3, 2, 4>
[E:\Program Files\Tencent\qq\LoginCtrl.dll] <><1, 0, 0, 1>
[E:\Program Files\Tencent\qq\npkcntc.dll] <INCA Internet Co., Ltd.><2006, 3, 2, 1>
[E:\Program Files\Tencent\qq\npkpdb.dll] <INCA Internet Co., Ltd.><2003, 10, 1, 1>
[E:\Program Files\Tencent\qq\QQRes.dll] <tencent><1, 0, 0, 1>
[E:\Program Files\Tencent\qq\QQMainFrame.dll] <N/A><N/A>
[E:\Program Files\Tencent\qq\CQQApplication.dll] <N/A><N/A>
[D:\WINNT\system32\quartz32.dll] <><4, 1, 0, 0>
[E:\Program Files\Tencent\qq\NewSkin.dll] <><1, 0, 0, 1>
[E:\Program Files\Tencent\qq\HostingMgr.dll] <><1, 0, 0, 1>
[E:\Program Files\Tencent\qq\CameraDll.dll] <><1, 0, 0, 1>
[E:\Program Files\Tencent\qq\MailSummary.dll] <><1, 0, 0, 1>
[E:\Program Files\Tencent\qq\QQSpace.dll] <><1, 0, 0, 1>
[D:\WINNT\system32\msdmo.dll] <N/A><N/A>
[E:\Program Files\Tencent\qq\QQGroupMng.dll] <><1, 0, 0, 1>
[E:\Program Files\Tencent\qq\GroupLive.dll] <N/A><N/A>
[E:\Program Files\Tencent\qq\QQSettingCtrl.dll] <><1, 0, 0, 1>
[E:\Program Files\Tencent\qq\QQSysMsgMng.dll] <N/A><N/A>
[E:\Program Files\Tencent\qq\UserDefinedHead.dll] <><1, 0, 0, 1>
[E:\Program Files\Tencent\qq\QQPlugin.dll] <N/A><N/A>
[E:\Program Files\Tencent\qq\QQConfigPlugin.dll] <><1, 0, 0, 1>
[E:\Program Files\Tencent\qq\QRingMng.dll] <N/A><N/A>
[E:\Program Files\Tencent\qq\PhoneAPI.dll] <><1, 0, 0, 1>
[E:\Program Files\Tencent\qq\DialerAllinOne.dll] <tencent><1, 4, 0, 0>
[E:\Program Files\Tencent\qq\QQAvatar.dll] <N/A><N/A>
[E:\Program Files\Tencent\qq\FlashAvatarDll.dll] <><1, 4, 0, 1>
[E:\Program Files\Tencent\qq\LongConnection.dll] <tencent><5, 0, 200, 160>
[E:\Program Files\Tencent\qq\QQPet.dll] <><1, 0, 0, 1>
[E:\Program Files\Tencent\qq\BQQApplication.dll] <N/A><N/A>
[E:\Program Files\Tencent\qq\CommercesMng.dll] <><1, 0, 0, 1>
[E:\Program Files\Tencent\qq\PersonalDesktop.dll] <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
[E:\Program Files\Tencent\qq\QQAddr.dll] <深圳市腾讯计算机系统有限公司><5, 0, 101, 200>
[E:\Program Files\Tencent\qq\QQSceneMng.dll] <N/A><N/A>
[E:\Program Files\Tencent\qq\QQPhoneHelper.dll] <腾讯科技(深圳)有限公司><2, 0, 6, 60>
[E:\Program Files\Tencent\qq\QQAllInOne.dll] <N/A><N/A>
[E:\Program Files\Tencent\qq\SCCore.dll] <N/A><N/A>
[E:\Program Files\Tencent\qq\QQCustomFace.dll] <N/A><N/A>
[D:\WINNT\system32\Macromed\Flash\Flash8.ocx] <Macromedia, Inc.><8,0,22,0>
[E:\Program Files\Tencent\qq\ImageOle.dll] <TODO: <Company name>><1.0.0.1>
[E:\Program Files\Tencent\qq\GroupConnection.dll] <Tencent><5, 0, 202, 170>
[E:\Program Files\Tencent\qq\QQMagicFace.dll] <><1, 0, 0, 1>
[E:\Program Files\Tencent\qq\QQZip.dll] <tencent><0, 3, 2, 4>
[E:\Program Files\Tencent\qq\QQOneClick.dll] <><1, 0, 0, 1>
[E:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scr_ch_pg.dll] <Kaspersky Lab><1.0.6.299>
[E:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\klscav.dll] <Kaspersky Lab><6.0.0.299>
[PID: 1124][E:\Program Files\Tencent\qq\TIMPlatform.exe] <tencent><0, 3, 1, 8>
[E:\Program Files\Tencent\qq\TIMProxy.dll] <tencent><0, 3, 2, 4>
[PID: 800][E:\Program Files\Tencent\qq\QZone\QZone.exe] <腾讯公司><1, 1, 101, 25>
[PID: 1232][D:\Program Files\Internet Explorer\iexplore.exe] <Microsoft Corporation><6.00.2800.1106>
[d:\program files\google\googletoolbar2.dll] <Google Inc.><3, 0, 131, 0>
[e:\Program Files\Tencent\QQ\QQIEHelper.dll] <深圳市腾讯计算机系统有限公司><1, 1, 0, 5>
[D:\WINNT\system32\quartz32.dll] <><4, 1, 0, 0>
[E:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scr_ch_pg.dll] <Kaspersky Lab><1.0.6.299>
[E:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\klscav.dll] <Kaspersky Lab><6.0.0.299>
[E:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prloader.dll] <Kaspersky Lab><6.0.0.299>
[D:\WINNT\system32\Macromed\Flash\Flash8.ocx] <Macromedia, Inc.><8,0,22,0>
[PID: 1068][E:\游戏安装\sreng2\SREng2\SREng.exe] <Smallfrogs Studio><2.0.21.505>
[D:\WINNT\system32\quartz32.dll] <><4, 1, 0, 0>
© 2000 - 2026 Rising Corp. Ltd.